Directory Permission Vulnerability in Hitachi Ops Center Analyzer
CVE-2022-3884

7.3HIGH

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
28 February 2023

Summary

A vulnerability exists in Hitachi Ops Center Analyzer due to incorrect default permissions that could allow local users to access, read, and modify sensitive files. This flaw primarily impacts the RAID Agent component of the software, compromising data integrity and potentially allowing unauthorized actions by users on affected versions. Users are advised to update to versions 10.9.0-01 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

Hitachi Ops Center Analyzer Windows 10.9.0-00 < 10.9.0-01

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.